DuoKey logotype

Security at DuoKey

Security and privacy at DuoKey

Protecting sensitive data starts with how we build, operate and govern our own technology. Security is integrated into DuoKey’s organisation, products and cryptographic architecture.

Visit our Trust Center

Governance

Security controls designed to be effective, consistent and auditable.

DuoKey establishes policies, assigns responsibilities, assesses risk and monitors the controls that protect our company, services and customers.

Security principles

How we approach security.

These principles guide how DuoKey protects its organisation, products and customers.

Least privilege

Access is limited to people with a legitimate business need and to the minimum permissions required for their role.

Defence in depth

Identity, endpoint, network, application and cryptographic safeguards are layered to reduce reliance on any single control.

Consistent controls

Security requirements apply across our people, suppliers, engineering practices, infrastructure and service operations.

Continuous improvement

We review risk, test safeguards and improve our security programme as technology, threats and customer needs evolve.

Security and compliance

Independent assurance of our security programme.

DuoKey maintains an ISO/IEC 27001:2022-certified information security management system and has completed a TISAX® assessment. Additional assurance material is available through our Trust Center.

ISO
ISO/IEC 27001:2022Information security management
TISAX
TISAX® assessmentAutomotive information security
TC
Trust CenterSecurity and compliance documents

Data protection

Designed so that control does not depend on one system or one party.

DuoKey distributes cryptographic control, keeps encryption keys under customer authority, and makes sensitive operations auditable.

Distributed cryptographic operations

DuoKey uses secure Multi-Party Computation to distribute cryptographic operations across independent nodes. No single node needs to hold the complete key material.

Customer-controlled encryption

Our products help organisations retain control of encryption keys while protecting sensitive workloads across cloud services, SaaS platforms and hybrid environments.

Traceable key operations

Access controls, lifecycle management and audit records provide visibility into sensitive cryptographic activity and support operational oversight.

Product security

Security throughout the product lifecycle.

Security is considered from architecture and implementation through release and production operation.

Secure development

Engineering changes are reviewed, tested and delivered through controlled development and release processes.

Security testing

Automated and targeted testing helps identify weaknesses in source code, dependencies, applications and infrastructure.

Vulnerability management

Potential vulnerabilities are assessed, prioritised and tracked through remediation according to their risk and impact.

Logging and monitoring

Security-relevant events and service health are monitored to support investigation, response and continuous improvement.

Enterprise security

Protecting the organisation behind the product.

Operational safeguards protect DuoKey’s people, devices, suppliers and internal services.

Identity and access

Strong authentication, role-based access and timely provisioning and deprovisioning protect internal services.

Endpoint protection

Corporate devices are centrally managed with encryption, malware protection, security configuration and update controls.

Security education

Employees receive security awareness training and practical guidance for recognising and responding to threats.

Vendor security

Third parties are assessed according to their access, data handling and potential impact on critical services.

Data privacy

Privacy is part of our security approach.

We process personal information for defined purposes, apply appropriate safeguards and support applicable data protection rights.

Read our Privacy Policy →

Purpose limitation

Personal information is collected and used for documented service, business and legal purposes.

Data subject rights

Individuals can exercise applicable rights relating to access, correction, deletion, restriction and objection.

Retention and suppliers

Personal information is retained only as needed, and service providers are expected to protect its confidentiality and security.

Responsible disclosure

Found a potential security issue?

Please report suspected vulnerabilities privately and include enough detail for our team to reproduce and assess the issue.

[email protected]
Avoid accessing or modifying customer data.
Do not interrupt services or use destructive techniques.
Provide the affected component, reproduction steps and potential impact.

DuoKey Trust Center

Review our security and compliance documentation.

Access certificates, policies and assurance information through the DuoKey Trust Center.